← Back to Django Course | Chapter 10: Authentication & Authorization | Lesson 9 of 12

Django में Password Hashing

Django आपका असली password कभी नहीं लिखता — यह इसे एक secret code में scramble करता है जो check किया जा सकता है लेकिन वापस पढ़ा नहीं जा सकता।
Syntax
markup
user = User.objects.get(username='name')
user.set_password('new_password')
user.save()

user.check_password('password')

Hashing क्यों मायने रखता है

अगर एक database कभी leak हो, hashed passwords एक attacker के लिए बिना enormous computing effort के useless हैं, plain text passwords के विपरीत जो instantly readable हैं।

उदाहरण: Why Hashing Matters

create_user() runs the password through Django's hasher automatically — the stored value is never the raw text.

bash
python manage.py shell

>>> from django.contrib.auth.models import User
>>> user = User.objects.create_user(username='bob', password='SecurePass1')
>>> print(user.password)
pbkdf2_sha256$600000$...

⚠️ Run this in your own terminal or Node.js environment.

एक Password सुरक्षित रूप से बदलना

set_password() एक नया password फिर से hash करता है और इसके बाद change persist करने के लिए save() call होना चाहिए।

Note: set_password() के बाद हमेशा save() call करें — यह otherwise सिर्फ in-memory object update करता है।

उदाहरण: Changing a Password Safely

set_password() hashes the new password in memory; save() writes the hashed value to the database.

bash
python manage.py shell

>>> user.set_password('EvenSaferPass2')
>>> user.save()

⚠️ Run this in your own terminal or Node.js environment.

एक Password Verify करना

check_password() एक plain-text attempt को stored hash के against सुरक्षित रूप से compare करता है, True या False return करते हुए।

उदाहरण: Verifying a Password

check_password() re-hashes the guess and compares hashes, so the real password is never exposed in the process.

bash
python manage.py shell

>>> user.check_password('EvenSaferPass2')
True
>>> user.check_password('WrongGuess')
False

⚠️ Run this in your own terminal or Node.js environment.

Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. Plain-text passwords एक CharField में store करना बजाय Django के User model को इन्हें अपने आप hash करने देने के।
  2. user.password को सीधे एक submitted password string से compare करना बजाय check_password() या authenticate() उपयोग करने के।
  3. एक custom hashing function रोल करना बजाय Django के built-in, well-tested PASSWORD_HASHERS पर भरोसा करने के।
चैप्टर सारांश
  • Django PASSWORD_HASHERS में listed algorithms (default रूप से PBKDF2) उपयोग करके passwords अपने आप hash करता है।
  • create_user() और set_password() password को hash करते हैं; .password को directly assign करना ऐसा नहीं करता।
  • check_password() एक plain password को stored hash के against verify करता है बिना इसे कभी decrypt किए।
  • Passwords को कभी वापस इनके original text में un-hash नहीं किया जा सकता — सिर्फ verify किया जा सकता है।

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.